A cross-site scripting vulnerability in Trellix Central Management (CM) prior to 9.1.3.97129 allows a remote authenticated attacker to craft CM dashboard internal requests causing arbitrary content to be injected into the response when accessing the CM dashboard.
2024-02-13T10:15:08.227
2024-11-21T08:43:05.313
Modified
CVSSv3.1: 4.6 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | trellix | central_management_system | < 9.1.3.97129 | Yes |